{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acssom_projectcssom/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cssom_project:cssom:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93752"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CSSOM (\u003c= 0.5.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCSSOM through version 0.5.0 contains a denial of service (DoS) vulnerability located within the CSSStyleDeclaration.setProperty() method. The vulnerability arises from an improper validation of reserved property names. Specifically, the library fails to restrict the use of the property name 'length'.\u003c/p\u003e\n\u003cp\u003eAn attacker can leverage this flaw by providing a specially crafted stylesheet containing a declaration named 'length'. When processed, this declaration overwrites the library's internal counter, which leads to uncontrolled and excessive memory allocation during the cssText serialization process. This behavior results in a resource exhaustion state, causing the host process to terminate. This vulnerability impacts any application or environment utilizing CSSOM version 0.5.0 or earlier to parse or manipulate untrusted CSS input.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the termination of the process executing the CSSOM library. This can lead to service outages in applications that rely on CSSOM for dynamic style handling. The severity is high, as the attack vector involves the submission of malicious CSS input, which is common in web-based applications that allow user-provided stylesheets or CSS customization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the CSSOM library to a version later than 0.5.0 once a patched release is made available by the maintainers. If an immediate update is not possible, implement input sanitization to block any CSS declarations named 'length' from being passed to the CSSStyleDeclaration.setProperty() method.\u003c/p\u003e\n","date_modified":"2026-09-18T20:07:23Z","date_published":"2026-09-18T20:07:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cssom-dos/","summary":"The CSSOM library up to version 0.5.0 is vulnerable to a denial of service attack via malicious CSS declarations that trigger excessive memory allocation.","title":"Denial of Service Vulnerability in CSSOM CSSStyleDeclaration.setProperty","url":"https://feed.craftedsignal.io/briefs/2026-09-cssom-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cssom_project:cssom:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}